Select this option to allow the GlobalProtect
app to determine if it is inside the enterprise network. This applies
to endpoints when a tunnel is not required in the enterprise network
or when the endpoints are configured to communicate with internal
gateways. Choosing the internal host detection feature is a best
practice for these endpoints. Configuring internal gateways is however
optional. When the user attempts to log in, the app does a
reverse DNS lookup of an internal host using the specified IP Address to
the specified Hostname. The host serves as
a reference point that does not have to be reachable but reverse
DNS lookup should be successful only when the endpoint is inside
the enterprise network. If the app finds the host, the endpoint
is inside the network and the app connects to an internal gateway,
if configured, or the GlobalProtect app shows the connection status
as internal. If the app fails to find the internal host, the endpoint
is outside the network and the app establishes a tunnel to one of
the external gateways. The IP address type can be IPv4 (IPv4
traffic only), IPv6 (IPv6 traffic only),
or both. Use IPv4 and IPv6 if your
network supports dual stack configurations, where IPv4 and IPv6
run at the same time. The IP address must be compatible with the IP address type.
For example, 172.16.1.0 for IPv4 or 21DA:D3:0:2F3b for IPv6. If you choose IPv4 and IPv6,
enter the appropriate IP address type for each.
|